We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

HitmanPro scanner guide · current build, support and community failure modes checked August 10, 2026

How to Use HitmanPro as a Second-Opinion Scanner

HitmanPro is most useful after something specific happened: a suspicious download, redirect, detection disagreement or unexplained Windows behavior. Keep the primary antivirus active, run one focused second opinion, save the log before remediation and make the result part of an evidence chain—not a panic button.

On-demand, not residentOne scanner at a timeSave log firstRescan after cleanup

Quick answer: download the current scanner from the official Sophos HitmanPro page, save browser work, keep Microsoft Defender or the intended primary antivirus active, and run the normal scan for a meaningful second opinion. Review every finding before pressing Next, save the log, quarantine or remove only supported detections, complete any requested reboot and scan again. A clean scan is useful evidence, not proof that compromise is impossible.

RoleSecond opinion
Primary AVKeep active
Disputed fileSave log
Cleanup proofRestart + rescan

HitmanPro is an on-demand second opinion, not the primary shield

The ordinary HitmanPro scanner is a small Windows cleanup tool designed to run beside existing antivirus protection. It checks active processes, startup locations, files and remnants using local classification and cloud-assisted analysis. When the window closes, it isn't continuously inspecting every new file like a resident antivirus.

That distinction is the reason to use it. Microsoft Defender, Bitdefender or another supported primary product keeps watching in real time; HitmanPro provides a fresh classification path after a concrete event. The two jobs are complementary as long as the on-demand scanner doesn't get mistaken for permanent protection.

HitmanPro.Alert is a different installed product with resident exploit, ransomware and privacy layers. If the task is configuring Alert, this is the wrong guide. Our scanner-versus-Alert comparison separates the products, and the current HitmanPro review explains the evidence gap behind the broader buying decision.

A second opinion is also not a vote. Two tools can use overlapping cloud intelligence, disagree about potentially unwanted software or inspect different scopes. Treat the result as another piece of evidence, not a mathematical guarantee created by counting scanner names.

Use HitmanPro after a specific signal, not as a daily anxiety ritual

Good triggers include a suspicious download, fake-update page, browser redirect, primary-antivirus disagreement, unexplained persistence, a newly disclosed compromise involving software you ran, or a cleanup that needs verification. Write down what happened, when it happened, which account or file was involved and what the primary antivirus reported. That context determines whether a detection matters.

A second opinion adds less value when the machine has no symptom, current protection is healthy and several recent scans are already clean. A March 2026 r/antivirus discussion captures the stopping problem: adding a third or fourth scanner doesn't help if the user has no rule for trusting any outcome. Define the decision before scanning.

SituationHitmanPro valueDecision after scan
Suspicious download was openedChecks active and remnant evidenceCorrelate file, time, primary AV and symptoms
Primary AV flags a disputed fileIndependent classification pathSave both logs; don't use majority voting alone
Cleanup just completedVerification for remaining activityRestart, rescan and watch symptoms
Browser redirects or PUA symptomsCurrent build targets Chromium PUA extensionsReview extension/account/browser state too
Several clean scans; no symptomsDiminishing returnsStop or escalate based on incident risk
Account theft or high-value compromiseOnly one endpoint signalUse incident response and trusted-device actions

Prepare the PC so the scan result remains usable evidence

Save documents and browser forms first. Build 338 release notes document prompts and settings around closing Chromium browsers for cookie access, and a current community question shows how alarming an unexpected browser closure can look. Avoid that surprise by finishing sensitive sessions before the scan.

Keep the primary antivirus enabled. Update Windows and the primary provider, but don't erase the suspicious file, clear all browser data or run multiple cleanup utilities before preserving the original detection and path. If this is a work device or a financial incident, follow the administrator or incident-response process before changing evidence.

Record the Windows edition/build, HitmanPro build, primary provider and trigger. If full-disk encryption, a failing drive or recent power loss is involved, back up important data. Disk repair and malware remediation can both expose existing storage problems.

Disconnecting from the network can be appropriate during a live compromise, but HitmanPro is cloud-assisted and may need connectivity for its normal classification path. Don't reconnect a clearly compromised machine just to make a consumer scan work; use a trusted incident-response route instead.

Download the current scanner from Sophos and verify the file

Use the current official downloads page, which provides separate 64-bit and 32-bit scanner binaries. Most current Intel/AMD Windows systems use x64. ARM support has its own current behavior, so follow the architecture wording on the live page rather than a mirror's old filename advice.

Open file Properties → Digital Signatures and expect the current Sophos publisher chain. Build 338 changed the code-signing certificate to Sophos Ltd, and build 346 refreshed Sophos branding. A valid expected signature plus an official HTTPS source is stronger provenance than a third-party download badge.

The current release page identifies build 346 from February 5, 2026. It added Chromium PUA-extension detection/removal, shows Disk Access Mode in the title bar, improved hardening and fixed ARM scanning and uploads. Check the live page again if the downloaded build differs; newer isn't suspicious by itself.

Don't upload a proprietary or personal executable to a public multi-engine service casually. VirusTotal's false-positive guidance is useful for vendor escalation, but public scanning can disclose samples and metadata. Use the software vendor and HitmanPro support route when confidentiality matters.

Run the scanner once or save an installed convenience copy

Open the verified download. The official installation sequence says the first Next starts a scan; later prompts can save HitmanPro on the PC and create shortcuts. For one second opinion, the run-once path is enough. For periodic use, saving the copy makes updates and shortcuts more convenient.

Neither choice turns ordinary HitmanPro into a resident antivirus. Installation here means application registration and convenience, not a permanent real-time shield. Keep the existing primary provider active in both cases.

If you later want a clean exit, the complete uninstall guide distinguishes the portable EXE, installed scanner and HitmanPro.Alert. Don't delete Alert as though it were a run-once scanner.

Accept current terms only after reading them. The present 30-day trial requires no credit card, but scanning rights, removal rights and a paid license are different questions. Our pricing guide covers that boundary without mixing it into the detection decision.

Choose the normal scan for evidence; use Quick Scan for a narrower check

The normal/default scan is the practical starting point after a suspicious event. It gives HitmanPro room to inspect its intended active, startup, file and remnant signals. Let the scan finish unless the PC becomes unsafe or storage health is in doubt; stopping at a scary filename can remove the context that appears at the result stage.

Quick Scan was introduced for load-point locations and in-memory objects. It's useful when the question is whether malware appears active now or when a faster follow-up is appropriate. It isn't a full inventory of every file on every attached drive, and a clean Quick Scan should never be described as “the whole computer is proven clean.”

NeedReasonable choiceLimit to remember
First second opinion after a risky eventNormal/default scanStill not a forensic disk image
Fast check for active persistenceQuick ScanNarrower scope
Verify cleanup after restartRepeat the same meaningful modeCompare logs, not just colors
Scanner freezes in direct accessCompatible Disk Mode after official repair orderCompatibility can reduce low-level visibility
One file/folder concernUse supported context scan if current build exposes itHistorical folder scans weren't always recursive

Avoid historical expert modes and command-line switches unless current support directs them for the exact build. Release notes preserve years of features, including Early Warning Scoring, but old availability isn't proof that every consumer should use it in 2026.

Expect browser prompts when cookie and extension data are in scope

Chromium browsers can keep cookie databases locked while running. Current build history says HitmanPro added a running-browser prompt and a close-browser-process setting, and recent builds improved Chromium PUA extension and tracking-cookie handling. Save tabs, drafts and authenticated work before starting.

A browser closing during an official HitmanPro scan is therefore not, by itself, evidence that the scanner is malicious or that the browser was compromised. Verify the download source and signature, then compare the behavior with the current prompt/settings. If the process closes without any visible scan or the file came from a mirror, stop and investigate the binary.

Tracking cookies, a PUA extension and credential-stealing malware aren't the same severity. Don't tell a user to change every password because a tracking cookie was listed. Conversely, removing a cookie doesn't resolve a malicious extension, stolen session or account takeover.

After cleanup, review the browser's extensions, notification permissions, startup pages, search provider and signed-in sessions. HitmanPro can contribute evidence, but the browser/account controls own those settings.

Use a six-stage evidence workflow instead of pressing Next blindly

A safe scan has a beginning and an acceptance test. Prepare and preserve context; scan with the primary shield active; review categories and paths; save the log; remediate supported findings; restart and verify. The order prevents a disputed file from disappearing before anyone can explain it.

HitmanPro evidence workflow from scan preparation through log, quarantine, restart and rescan
The red boundary matters: preserve a disputed or business-critical file and its log before irreversible deletion.

Don't let the result screen choose the incident story for you. The path, signature, parent application, persistence point, source and corroboration determine whether a red or amber entry is material. A tracking item in a browser profile isn't equivalent to an unsigned executable launching from a temporary directory.

If a known application stops working after quarantine, don't restore everything automatically. Confirm which item was moved, verify it with the publisher or support, and restore only when the evidence supports a false positive. A broken application can be reinstalled from a clean official source; restored malware can restart the incident.

Read malware, suspicious, unwanted and cookie results differently

A confirmed malware classification with corroborating engines, an unexpected path and active persistence deserves prompt containment. Preserve the log, let the supported remediation act, note any restart instruction and avoid using sensitive accounts until verification is complete.

Suspicious or single-engine results need more judgment. Check the full path, publisher signature, file age, expected parent software and whether the primary antivirus agrees. A business tool, mod, emulator, script or newly signed binary can look unusual without being safe—or malicious—on that fact alone.

Potentially unwanted applications sit between security and user choice. Bundled extensions, ad injectors and system optimizers may be intentionally installed but still create risk or friction. Remove them when their behavior is unwanted, but don't write “trojan removed” when the actual result was a PUA.

Result typeEvidence to inspectConservative action
Known malwarePath, persistence, engines, active stateSave log, quarantine/remove, restart, rescan
Suspicious/unknownSignature, source, behavior, corroborationHold action on critical files; verify
PUA/adwareInstall consent, extension behavior, bundlerRemove if unwanted; repair browser settings
Tracking cookieBrowser/profile and privacy contextClear as privacy hygiene, not malware proof
System repair/remnantOriginal incident and proposed changeBack up and verify before repair
CleanMode, scope, updates and remaining symptomsUse as one evidence point

Expand details before applying one action to all findings. Convenience controls can erase the distinctions that matter most. A user who reviews six items for two minutes often avoids hours of false-positive recovery.

Save the log before changing a disputed or important file

HitmanPro's official false-positive article gives a direct route: scan once more, click Save log at the bottom left, and send the log with a short explanation to support. The log captures classifications and paths more accurately than a cropped red row.

Official HitmanPro support instruction to rescan and save the log for a possible false positive
Current official support page captured August 10, 2026. Save the log before deleting or restoring a disputed file.

Include the product build, Windows build, file source, whether the file is signed, why it's expected and what the primary antivirus reported. Don't email passwords, an entire private dataset, the full product key or a confidential sample without an approved secure transfer path.

Support confirmation is stronger than guessing from a file name. If a publisher also confirms the exact signed hash, keep that evidence with the HitmanPro response. When the file is genuinely malicious, the same log becomes the baseline for the post-remediation scan.

Quarantine supported findings, complete the restart and scan again

Prefer a reversible supported quarantine over manual deletion when the product offers it. Review each proposed action, then let HitmanPro perform the remediation. Don't simultaneously run another cleanup utility, edit the registry or delete the parent folder; overlapping changes make failures hard to diagnose.

If HitmanPro requests a restart, treat it as part of the cleanup. Save work, reboot normally and let scheduled remediation finish. Then update the primary antivirus, confirm its resident protection is healthy and repeat a meaningful scan. Compare the new log with the original rather than celebrating an empty window without context.

GateEvidence to retainPass condition
Pre-actionOriginal log and proposed actionCritical/disputed files reviewed
Quarantine/removalAction result and item pathNo unsupported bulk deletion
RestartPrompt completed and boot resultNo pending-remediation warning
Primary protectionProvider and update stateResident antivirus healthy
Verification scanNew log using meaningful modeConfirmed finding gone
Symptom checkOriginal trigger retested safelyNo recurrence or escalation opened

A finding that returns at the same path can indicate persistence, synchronization, a managed installer, browser account sync or incomplete remediation. Record what recreates it and escalate. Repeatedly deleting the same file without identifying its source isn't cleanup.

For broader recovery decisions, use our malware-removal hub. If the only remaining task is removing the scanner, use the dedicated uninstall guide after evidence and quarantine decisions are settled.

If the scan freezes, follow the official disk-integrity order

The current official scan-freeze article says corrupted NTFS indexing is a common cause after a crash or power loss. Its order is to run chkdsk /f from an administrator command prompt, then sfc /scannow, and try the scan again.

Back up important data first. A freeze near the same disk location can be a storage-health warning, and CHKDSK changes filesystem state. If the drive reports hardware errors, prioritize data recovery and disk diagnostics over forcing another malware scan.

If the freeze remains, HitmanPro says to open Settings → Advanced and change Disk mode from Direct to Compatible. Compatible mode uses Windows APIs and is intended to avoid low-level conflicts, but historical release documentation notes a visibility tradeoff for complex rootkits. Record which mode produced the result.

Don't jump straight to disabling the primary antivirus. The official sequence repairs disk/system integrity and changes HitmanPro's access mode. If the machine still freezes, send the build, stop point, logs and storage context to support.

Use a fresh scanner from USB without reviving old Kickstart advice

Current HitmanPro copy says the lightweight scanner can run after download from a PC or USB drive. On a trusted computer, download the correct current binary from Sophos, verify its signature, copy it to a clean USB drive and eject safely. On the target PC, preserve incident context and run it as the ordinary on-demand scanner.

Don't reuse a years-old scanner stored in a rescue drawer. A current binary matters because cloud endpoints, code-signing, Windows support and detection logic change. Keep the USB physically and logically controlled if it moves between an infected and clean environment.

HitmanPro.Kickstart was an old bootable ransomware-rescue feature. Search still surfaces historical instructions, but that isn't the same as running the current portable scanner from USB. Don't format a drive or follow legacy boot steps unless current official support specifically restores that workflow for the exact product.

A portable scanner doesn't make an infected Windows session trustworthy. If malware blocks tools, steals credentials or controls boot, use a current vendor rescue environment or professional incident-response process rather than improvising with obsolete boot media.

Keep the primary antivirus active and run one on-demand scanner at a time

HitmanPro's core product promise is coexistence: no need to uninstall the current antivirus. That applies to the ordinary on-demand scanner. It doesn't mean every combination of multiple resident real-time products is conflict-free.

Leave Defender, Bitdefender or the chosen provider active. Pause heavy backup/indexing work if necessary, then run only one second-opinion scan at a time. Concurrent full scans compete for disk access, can trigger each other's temporary files and make browser or quarantine behavior harder to attribute.

After the scan, verify Windows Security still names the expected primary provider. If you installed HitmanPro.Alert instead of the ordinary scanner, you changed the resident stack and need the compatibility/buying guidance for Alert. The Microsoft Defender review covers the built-in baseline.

Community consensus is useful here only as a direction, not a guarantee for a particular PC. Test on the actual workload, preserve logs and simplify the stack if applications, browsers or games become unstable.

A clean scan is a confidence update, not proof of absence

A clean normal scan from a current official build, alongside an updated primary antivirus and no continuing symptoms, is meaningful reassurance after a low-risk event. Document the date, trigger, scan mode and result, then stop adding tools unless new evidence appears.

It isn't enough when accounts show unauthorized sessions, files are encrypted, security controls were disabled, persistence returns, a work tenant reports compromise or the PC holds high-value secrets. Those cases require credential actions from a trusted device, logs beyond antivirus, administrator involvement or a known-clean rebuild.

Absence of detection also can't verify that a downloaded program behaved ethically. Adware, privacy-invasive software and credential collection can sit outside a classic malware label. Review the program's source, permissions, network/account changes and uninstall it when trust is gone.

Set a stopping rule before the scan: “If the primary and HitmanPro are clean, updates and provider status are healthy, and the symptom does not recur, I stop. If a high-risk signal remains, I escalate.” That converts anxiety into a testable decision.

Cloud-assisted scanning needs a data-handling decision

HitmanPro relies on cloud intelligence and can upload suspicious files for classification. That improves verdict quality, but a proprietary executable, legal document, medical export or customer dataset may require an approved handling route. Review current scanner settings and organization policy before scanning confidential material.

Historical release notes document controls related to automatic uploads, but old command-line switches aren't a substitute for current consumer documentation. If local-only handling is mandatory, ask current HitmanPro support what the exact build sends and whether the required scan path can meet the policy.

Logs can also expose usernames, folder paths, application names and incident details. Redact only what support doesn't need, transfer through the official case channel and don't post the complete log publicly by default. Preserve an original secure copy for the incident record.

The scanner's privacy boundary is one factor in product choice. The Antivirus-Review.com privacy policy governs this site, not HitmanPro uploads; vendor questions belong to Sophos/HitmanPro support.

HitmanPro second-opinion scanner FAQ

Can HitmanPro replace my antivirus?

No. Ordinary HitmanPro is an on-demand second-opinion scanner, not a continuous real-time antivirus. Keep Microsoft Defender or another supported primary provider active. HitmanPro.Alert is the separate installed product with resident defensive layers.

Can I run HitmanPro with Microsoft Defender or Bitdefender?

The ordinary scanner is designed to run beside an existing antivirus and doesn't need a second real-time engine. Keep the primary provider active, but run one on-demand scanner at a time so disk load, browser handling and remediation decisions remain understandable.

Should I use the default scan or Quick Scan?

Use the normal/default scan for a meaningful second opinion after a suspicious download, redirect or unexplained behavior. Quick Scan focuses on active locations such as memory and load points and is useful for a faster check. It isn't evidence that every file on every drive was examined.

Why did HitmanPro close my browser during a scan?

Current build history documents browser-closing prompts and settings for tracking-cookie access because Chromium browsers can lock their cookie data while running. Save browser work before scanning and verify the scanner came from the official source. Browser closure alone doesn't prove compromise.

What should I do if HitmanPro finds a suspicious file?

Don't treat every amber or disputed result as confirmed malware. Record the detection, path and proposed action, save the log and check whether the file is signed, expected and corroborated. For a possible false positive, HitmanPro support says to scan again, save the log and send it with a short explanation.

Should I delete or quarantine a HitmanPro detection?

Quarantine is generally safer than irreversible deletion when the product offers it, because it preserves a recovery and support path. For a confirmed active threat, follow the supported remediation action, restart if requested and rescan. Never restore a file merely because an application stops working.

Does a clean HitmanPro scan prove the PC is safe?

No scanner proves absence of compromise. A clean result is useful evidence when the download source, primary antivirus, updates and symptoms also look healthy. Persistent account theft, unauthorized changes, rootkit-level symptoms or a high-value incident require broader investigation or a known-clean rebuild.

Can I run HitmanPro from a USB drive?

Yes. Current HitmanPro product copy says the small scanner can run after download from a computer or USB drive. Obtain a fresh binary from the official page, verify it on a trusted PC and avoid treating old HitmanPro.Kickstart bootable-USB instructions as the normal current scanner workflow.

What if HitmanPro freezes during a scan?

Preserve where the scan stopped. HitmanPro's official troubleshooting says to run chkdsk /f, then sfc /scannow, and retry. If it still freezes, open Settings, Advanced and change Disk mode from Direct to Compatible. Back up important data before disk repair.

Is HitmanPro free to scan and remove malware?

The current product offers a 30-day trial with no credit card required. Scanning and paid removal rights aren't the same thing, and terms can change. Verify the current screen and order before relying on cleanup for a second device or after the trial; billing and removal are separate from scan interpretation.

Verdict: use HitmanPro to improve a decision, not replace one

HitmanPro works best as a focused second opinion beside a known primary antivirus. Start with a real trigger, use the current signed build, save browser work, choose a scan whose scope matches the question and let it finish. The result is evidence to interpret, not a command to delete every colored row.

Save the log before changing a disputed file. Quarantine supported threats, complete the restart and rescan. When a scan freezes, follow the official disk-repair and Compatible Mode order. When symptoms or account evidence outrun a consumer scan, stop adding tools and escalate.

The strongest outcome isn't “HitmanPro found nothing” or “HitmanPro found seven items.” It's a documented chain: source and trigger known, primary protection healthy, findings classified, actions reversible where possible, cleanup verified and a stopping rule applied.